Threat Intelligence in Practice: From Data to Decisions
Most security organizations have access to threat intelligence in some form — IOC feeds, news reports, vendor alerts. But there is a vast difference between having access to threat information and actually using it to improve security decisions. Threat intelligence that is not turned into action is just noise.
The Levels of Threat Intelligence
Threat intelligence operates at four levels, and all are important:
Strategic Intelligence
Aimed at leadership and decision-makers. Focuses on trends, motivations, and capabilities of threat actors relevant to your industry and region.
- Which threat groups target your sector?
- What are the dominant attack trends for the next year?
- Which geopolitical factors influence the threat landscape?
Strategic intelligence drives investment decisions and security strategy.
Operational Intelligence
Aimed at security managers and SOC leadership. Focuses on specific campaigns, threat actor tactics, and planned attacks.
- Which campaigns are targeting our sector right now?
- What vulnerability exploitation techniques are the actors using?
- What is the expected attack vector?
Operational intelligence drives prioritization and resource allocation.
Tactical Intelligence
Aimed at security analysts and detection engineers. Focuses on TTPs (tactics, techniques, and procedures) used by threat actors.
- Which MITRE ATT&CK techniques does the actor use?
- How is initial access achieved?
- Which lateral movement techniques are preferred?
Tactical intelligence is used to build detection rules and improve defenses.
Technical Intelligence
Aimed at automated systems and analysts at the operational level. Focuses on specific IOCs (Indicators of Compromise).
- IP addresses, domains, and URLs used in attacks
- File hashes for malware
- Email addresses used in phishing
Technical intelligence has a short shelf life — IP addresses change, domains are rotated. But it is valuable for detecting ongoing compromises.
IOCs vs. TTPs: Why TTPs Matter More
IOCs (IP addresses, domains, hashes) are easy to consume and match automatically. But they have a fundamental weakness: the attacker can change them trivially. A new domain, a new IP, a recompiled binary — and the IOCs are worthless.
TTPs (tactics, techniques, and procedures) are far harder to change. An attacker's preferred method for lateral movement, persistence mechanism, or exfiltration technique often remains the same across campaigns. Detections based on TTPs have a much longer lifespan.
The **Pyramid of Pain** illustrates this concept: the higher up the pyramid (from hashes to TTPs), the more painful it is for the attacker to change — and the more valuable the detection is for the defender.
Sources of Threat Intelligence
Open Sources (OSINT)
- MITRE ATT&CK — — framework for threat actor techniques
- AlienVault OTX — — community-based IOC sharing
- Abuse.ch — — malware and botnet information
- CISA (Cybersecurity and Infrastructure Security Agency) — — US government advisories
- NCSC — — UK and Nordic cooperation and advisories
Commercial Feeds
- Vendor-specific feeds (Microsoft, CrowdStrike, Recorded Future)
- Industry-specific feeds tailored to your sector
Industry Networks and ISACs
- ISACs (Information Sharing and Analysis Centers) — — sector-specific intelligence sharing
- FS-ISAC — — for the financial sector
- H-ISAC — — for the healthcare sector
- Regional and national CERTs
Government Sources
- National cybersecurity agency advisories and threat assessments
- Annual threat reports from intelligence services
- Sector-specific guidance from regulatory bodies
From Intelligence to Action
This is the critical part. Threat intelligence that does not result in concrete actions is wasted effort. Here is how to operationalize it:
Enrich Alerts with Context
When an alert triggers, automatically enrich it with relevant threat intelligence. An alert for a known IOC should include information about the campaign, the threat actor, and recommended response actions.
Build Hunting Hypotheses
Use tactical intelligence to formulate hunting hypotheses: "Threat actor X uses technique Y for initial access in our sector. Let's hunt for this technique in our logs."
Prioritize Detection Development
TTPs from relevant threat actors should drive the prioritization of which detection rules get developed. Don't spend time building detections for techniques that are never used against your industry.
Inform Vulnerability Management
When a new vulnerability is announced, use threat intelligence to assess whether it is already being actively exploited and by whom. This drives patch prioritization.
Integration with Microsoft Sentinel
Sentinel has built-in support for threat intelligence:
- Threat Intelligence connectors — import IOCs from multiple sources
- TI-matching analytics — automatically correlate IOCs against log data
- Threat Intelligence workbook — provides an overview of imported indicators
- Hunting notebooks — use TI data to structure threat hunting
Common Mistakes
- Collecting without acting — — dozens of feeds with millions of IOCs that nobody actively uses
- Only technical level — — matching IOCs automatically while ignoring strategic and tactical levels
- No feedback loop — — detections triggered by TI data are never evaluated for quality
- Wrong context — — IOCs from irrelevant regions or sectors only create false positives
- No sharing — — receiving intelligence from others but never sharing back
ForSec helps organizations build effective threat intelligence programs — from selecting sources and integrating with Sentinel, to processes that ensure intelligence actually improves security.
Need help with cybersecurity?
We help Norwegian organizations protect against digital threats. Contact us for a no-obligation conversation.
Contact us